AES Encrypt / Decrypt
CryptoAES-GCM symmetric encryption with a PBKDF2-derived key, random salt and IV. Password-based.
On this page
What is symmetric encryption?#
Symmetric encryption uses one shared secret for both locking and unlocking. You give it plaintext plus a password; it returns a scrambled blob that nobody can read back without that same password. It is the right tool whenever you want confidentiality — hiding what something says — as opposed to a hash (which only proves integrity) or HMAC (which proves authenticity).
This page uses AES-GCM, the authenticated-encryption mode recommended for new code. “Authenticated” is the key word: GCM does not just scramble your text, it also weaves in a tamper-proof tag. If anyone flips a single bit in the ciphertext, decryption fails loudly instead of silently returning garbage. The key is derived from your password with PBKDF2 over SHA-256, using a fresh random salt and 100,000 iterations by default, so a weak-ish password is still expensive to brute-force offline.
Everything runs in the browser through Web Crypto. There is no server, no key escrow, and no network call — if you lose the password, the ciphertext is unrecoverable, by design.
How to use it#
- Pick a mode: Encrypt (plaintext in → ciphertext out) or Decrypt (ciphertext in → plaintext out).
- Type the password. It is the single shared secret; whoever decrypts later must type the exact same one.
- Choose the options:
- Key bits — 128 / 192 / 256 (default 256). 256 is the modern baseline; the others exist for matching legacy systems.
- Iterations — PBKDF2 rounds, default 100,000. Higher slows down offline cracking but also slows you down; 100,000 is a sensible floor today.
- Encoding — base64 (compact, the default) or hex.
- Paste the input into the left pane. For encrypt, any text; for decrypt, the blob you previously copied out.
- Read the output on the right. The status line tells you whether the operation succeeded; a wrong password on decrypt shows a clean failure rather than corrupted text.
Key features#
- AES-GCM authenticated encryption. Tampering with the ciphertext is detected — a modified blob refuses to decrypt rather than producing plausible garbage.
- Self-describing output. The salt, IV, key size, and iteration count are packed into the output blob, so decryption needs nothing but the password. You never have to remember or re-send those parameters separately.
- Per-message randomness. A new random salt and a new 12-byte IV are drawn for every encryption, so encrypting the same text twice yields two completely different blobs — both decrypt to the same plaintext.
- Tunable PBKDF2. Raise the iteration count to harden a weak password against offline attack.
- Zero upload. Encryption and decryption are both local; the password and plaintext never leave the page.
Worked example#
Encrypt the message launch at dawn with the password correct-horse-battery-staple, key bits 256, iterations 100000, encoding base64. The output below is a real, verifiable blob — paste it straight into Decrypt with the same password and launch at dawn comes back:
AQEAAAGGoPVkwA9k0rjoWLw8GXnalIvQoBTP+awUg4DczQwTK5nxMwUaEaQ35WTQbWK8gLMkvuDf+/ndr04f8fw=
(Encrypting the same text again will produce a different blob, because the salt and IV are freshly random each run.) That blob is not just ciphertext. It is a tiny envelope laid out as:
version(1) | keyBits(2) | iterations(4) | salt(16) | IV(12) | ciphertext+tag
Switch to Decrypt, paste the blob above back into the input, type the same password, and the right pane returns launch at dawn. Now retry the decrypt with a slightly different password — GCM’s authentication tag will not validate, and the status line reports a failure instead of handing you half-corrupted text. That clean failure is exactly what authenticated encryption buys you over the older, unauthenticated CBC mode.
FAQ#
What if I forget the password?#
The data is gone. PBKDF2 and AES are designed so that the password cannot be recovered from the blob — there is no “forgot password” path, no backdoor, and no server that could reset it. Treat the password as the single point of failure, and consider storing critical passwords in a password manager.
Why does encrypting the same text twice give different output?#
Because a new random salt and a new random 12-byte IV are generated for every encryption. This is deliberate: if identical plaintext always produced identical ciphertext, an attacker could recognise repeated messages. The randomness does not affect decryption, because the salt and IV travel inside the blob and are read back automatically.
How many iterations should I set?#
100,000 is a reasonable floor for interactive use. If you are protecting something high-value and can tolerate a brief wait, 600,000 brings a meaningful additional cost to an attacker without being painful for you. The cost is paid once per encrypt or decrypt, not per byte of data.
Is this safe for large files?#
It handles any text you can paste, but this is a page-sized tool, not a streaming file encryptor. For very large payloads, a hybrid scheme (AES for the data, RSA or key wrapping for the AES key) is the standard pattern — and AES-GCM is exactly the symmetric half of that pattern.